Identity Management System for Secure Attribute Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face challenges in securely managing multiple identities and information disclosure when transacting online, as they often struggle to determine what information is shared with websites and whether those sites are legitimate, leading to increased risks of identity theft and data breaches.
Innovation Solution
A method and system for integrating multiple identities and identity providers, which involves receiving a service provider's security policy, determining requested attributes, obtaining authenticated attributes from a trusted issuer, registering with a provisioning service, and accessing services based on these attributes, allowing users to control information dissemination and enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users disclose personal information to multiple websites for online transactions, then transaction convenience and comfort level increase, but the risk of identity theft and information theft increases
Solution Approach 1:
The patent segments personal information into distinct attributes (name, address, social security number, account numbers, credit card numbers, etc.) and organizes them into structured identity profiles. This segmentation allows users to selectively disclose only necessary attributes to specific websites rather than disclosing all personal information, thereby maintaining transaction convenience while reducing identity theft risk.
Solution Approach 2:
The patent introduces an intermediary identity management system that acts as a mediator between users and websites. This system verifies website legitimacy, manages attribute assertions, and controls information flow. The intermediary prevents users from directly disclosing sensitive information to potentially fraudulent sites while enabling secure transactions with legitimate services.
2Adaptability or versatility
If users transact with many different websites and user interfaces, then transaction variety and service access increase, but the ability to determine information disclosure and website legitimacy decreases
Solution Approach 1:
The patent creates a universal identity management framework that works across multiple websites and services. The system provides consistent functionality for attribute assertion, website verification, and information disclosure control regardless of which service provider is accessed. This universal approach enables users to transact with diverse services while maintaining consistent security and verification capabilities.
Solution Approach 2:
The patent implements feedback mechanisms where the identity management system continuously verifies website legitimacy through multiple checks and provides users with visibility into what information is being disclosed and to whom. The system feeds back confirmation of website authenticity and attribute assertion status to users, enabling informed decisions about information disclosure across different services.
3Reliability
If users are requested to reveal personal information for security verification, then transaction security improves, but the exposure to imitators stealing identity and money increases
Solution Approach 1:
The patent applies partial action by requiring users to disclose only the specific attributes necessary for verifying transaction security rather than all personal information. The system determines the minimum necessary attribute set for each transaction type and requests only those specific pieces of information, thereby maintaining security verification while minimizing information exposure to imitators.
Solution Approach 2:
The patent performs preliminary verification of website legitimacy and user identity through the intermediary system before transactions occur. The identity management system pre-authenticates users and pre-verifies website credentials, establishing security credentials in advance. This preliminary action ensures transaction security is established before any sensitive information is exchanged, preventing imitators from obtaining personal information under false pretenses.
Data Source
AI summary
Exemplary embodiments disclosed herein may include a method and system for integrating multiple identities and identity providers, including, receiving the security policy of a service provider, determining the attributes requested by the service provider, obtaining authenticated attributes requested by the service provider, registering with a provisioning service based at least in part upon the authenticated attributes, and accessing services of the service provider based at least in part upon the registration from the provisioning service.


